Barion Pixel

INFORMATION ON THE RIGHTS OF NATURAL PERSONS REGARDING THE PROCESSING OF THEIR PERSONAL DATA

INTRODUCTION

Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter referred to as the "Regulation" or "GDPR") on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC, requires the Data Controller to take appropriate measures to ensure that all information relating to the processing of personal data is provided to data subjects in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. Furthermore, the Data Controller must facilitate the exercise of the rights of the data subject.

The obligation to provide prior information to the data subject is also prescribed by Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information.

Golden Hook Ltd. qualifies as a Data Controller within the meaning of Section 3, Point 9 of Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information ("Info Act").

With the information provided below, we fulfill our statutory obligations.

This Privacy Notice shall be published on the Company's website and, upon request, shall also be provided directly to the data subject.

CHAPTER I – IDENTIFICATION OF THE DATA CONTROLLER

The issuer of this Privacy Notice, and the Data Controller, is:

Service Provider: Golden Hook Ltd.

Registered Office: 8 November Street, Környe 2851, Hungary

Tax Number: 32708996-2-11

Company Registration Number: 11-09-031352

Telephone: +36 70 256 5909

E-mail: iroda@goldenhook.hu

Website: www.goldenhook.hu

(hereinafter referred to as the "Company")

CHAPTER II – DATA PROCESSORS

A Data Processor is a natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the Data Controller (Article 4(8) GDPR).

The appointment of a Data Processor does not require the prior consent of the data subject; however, the data subject must be informed accordingly.

The Company therefore provides the following information.

1. IT Service Provider

The Company uses a Data Processor for the operation and maintenance of its website.

This Data Processor provides hosting services and, for the duration of the agreement concluded with the Company, processes the personal data submitted through the website. The processing activity consists of storing personal data on the server.

Hosting Provider

Company Name: Rackhost Zrt.

Registered Office: 41 Tisza Lajos Boulevard, Szeged 6722, Hungary

Company Registration Number: 06-10-000489

Tax Number: 25333572-2-06

Telephone: +36 1 445 1200

E-mail: info@rackhost.hu

Website: https://rackhost.hu

Payment Service Provider

Company Name: Barion Payment Zrt.

Registered Office: 4–20 Irinyi József Street, 2nd Floor, Budapest 1117, Hungary

Company Registration Number: 01-10-048552

Tax Number: 25353192-2-43

Telephone: +36 1 464 7099

E-mail: hello@barion.hu

Website: https://www.barion.com/

Electronic Invoicing Service Provider

Company Name: KBOSS.hu Kft. (Számlázz.hu)

Registered Office: 7 Záhony Street, Budapest 1031, Hungary

Company Registration Number: 01-09-303201

Tax Number: 13421739-2-41

Telephone: Online Customer Service

Contact: Via the Számlázz.hu website

Website: https://szamlazz.hu

2. Postal Services, Delivery, and Parcel Shipping

These Data Processors receive from the Company the personal data necessary for the delivery of ordered products (including the recipient's name, address, and telephone number) and use this information solely for delivering the purchased item.

The product may consist of a physical item, a gift voucher, or a coupon.

The Company's delivery partners include:

  1. Hungarian Post (Magyar Posta)
  2. DPD
  3. GLS
  4. FOXPOST

CHAPTER III – ENSURING THE LAWFULNESS OF DATA PROCESSING

3. Data Processing Based on the Data Subject's Consent

(1) If the Company intends to process personal data based on the data subject's consent, such consent shall be requested in accordance with the content and information specified in the data request form defined in the Company's Privacy Policy.

(2) Consent shall also be deemed to have been given if the data subject ticks a checkbox while visiting the Company's website, makes the relevant technical settings when using information society services, or performs any other statement or action that clearly indicates, in the given context, the data subject's agreement to the intended processing of their personal data. Silence, pre-ticked checkboxes, or inactivity shall therefore not constitute consent.

(3) Consent shall cover all processing activities carried out for the same purpose or purposes. Where processing serves multiple purposes, consent must be obtained separately for each purpose.

(4) If the data subject gives consent in the context of a written declaration that also concerns other matters—for example, the conclusion of a sales or service agreement—the request for consent must be presented in a manner that is clearly distinguishable from those other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such declaration that infringes the provisions of the GDPR shall not be legally binding.

(5) The Company shall not make the conclusion or performance of a contract conditional upon the data subject's consent to the processing of personal data that is not necessary for the performance of that contract.

(6) It must be as easy to withdraw consent as it is to give it.

(7) Where personal data has been collected based on the data subject's consent, the Data Controller may, unless otherwise provided by law, continue processing such data without obtaining additional consent if necessary for compliance with a legal obligation applicable to the Data Controller, even after the data subject has withdrawn their consent.

(8) Visitors are hereby informed that the fishing lakes are monitored by a camera surveillance system.

Accordingly, by accepting the General Terms and Conditions during the purchase or reservation process, visitors acknowledge and consent to video recordings being made of them.

(9) Each reservation is valid for 7 days and applies to one specific fishing peg.

4. Data Processing Based on Compliance with a Legal Obligation

(1) Where data processing is based on compliance with a legal obligation, the categories of personal data processed, the purpose of processing, the storage period, and the recipients of the data shall be governed by the applicable legal provisions.

(2) Data processing based on a legal obligation does not require the data subject's consent, as the processing is mandated by law. Before such processing begins, the data subject must be informed that the processing is mandatory. The data subject must also receive clear and detailed information regarding all relevant aspects of the processing, including in particular:

  1. the purpose and legal basis of the processing;
  2. the identity of the Data Controller and any Data Processor;
  3. the duration of the processing;
  4. the fact that the personal data is processed to comply with a legal obligation applicable to the Data Controller;
  5. the persons or entities that may have access to the personal data;
  6. the rights of the data subject and the available legal remedies.

In the case of mandatory data processing, this information may also be provided by publishing the relevant legal provisions containing the required information.

5. Facilitating the Exercise of the Data Subject's Rights

The Company shall ensure, in the course of all its data processing activities, that data subjects are able to exercise their rights in accordance with applicable data protection legislation.

CHAPTER IV – VISITOR DATA PROCESSING ON THE COMPANY'S WEBSITE – INFORMATION ON THE USE OF COOKIES

Scope of Processed Data

The website provides content that is accessible to any internet user without registration. However, certain content services and the newsletter function are available only to registered users. A registered user is a person who has been authorized by the Data Controller in accordance with its internal regulations. Registration is free of charge.

During registration, the Customer is required to provide the following personal data:

i. Customer's full name

ii. E-mail address

iii. Password created by the Customer

iv. Residential address

v. Telephone number

vi. Fishing license number

1. Information on the Use of Cookies

Visitors to the website must be informed about the use of cookies. Except for technically necessary session cookies, the visitor's consent must be obtained before cookies are stored.

2. General Information About Cookies

2.1.

A cookie is a piece of data sent by the visited website to the visitor's web browser (in the form of a variable name and value) so that it can be stored and later retrieved by the same website. A cookie may remain valid until the browser is closed or for an unlimited period of time.

With each subsequent HTTP(S) request, the browser sends these stored data back to the server, allowing the website to recognize the user and modify or retrieve information stored on the user's device.

2.2.

The purpose of cookies is to enable the proper operation of website services by identifying individual users (for example, recognizing that a user has logged in) and providing personalized functionality.

The potential risk is that users may not always be aware that cookies are being used and that cookies may allow the website operator or embedded third-party services (such as Facebook or Google Analytics) to track users and create user profiles. In such cases, the contents of cookies may be regarded as personal data.

2.3. Types of Cookies

2.3.1. Technically Necessary Session Cookies

These cookies are essential for the proper functioning of the website. Without them, many website functions would not operate correctly.

They are used, among other things, to:

  1. identify users,
  2. determine whether a user is logged in,
  3. remember shopping cart contents,
  4. maintain the current session.

Typically, only a session ID is stored in the cookie, while the remaining data is stored securely on the server.

From a security perspective, it is important that session IDs are generated securely. Improper generation could expose users to session hijacking attacks.

Some terminology refers to all cookies that are deleted when the browser is closed as "session cookies."

2.3.2. Preference Cookies

These cookies remember the user's preferences, such as how the website should be displayed.

Essentially, they store user preference settings within the cookie itself.

2.3.3. Performance Cookies

Although the name may be somewhat misleading, performance cookies generally collect information about how visitors use the website, including:

  1. browsing behavior,
  2. time spent on pages,
  3. clicks,
  4. website interactions.

These cookies are typically provided by third-party services such as Google Analytics and may be used for creating user profiles.

Further information about Google Analytics cookies is available at:

https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage

2.4. Managing Cookies

Accepting or enabling cookies is not mandatory.

You may configure your browser to reject all cookies or to notify you whenever a cookie is being sent.

Although most browsers automatically accept cookies by default, these settings can usually be modified to prevent automatic acceptance and to allow users to choose whether to accept cookies each time.

Information on cookie settings for the most popular browsers is available at:

Google Chrome

https://support.google.com/accounts/answer/61416?hl=hu

Mozilla Firefox

https://support.mozilla.org/hu/kb/sutik-engedelyezese-es-tiltasa-amit-weboldak-haszn

Microsoft Internet Explorer 11

http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-11

Microsoft Internet Explorer 10

http://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-10-win-7

Microsoft Edge

http://windows.microsoft.com/hu-hu/windows-10/edge-privacy-faq

Safari

https://support.apple.com/hu-hu/HT201265

Please note that disabling cookies may result in certain website features or services not functioning properly.

3. Information About Cookies Used on the Company's Website and Data Collected During Visits

3.1. Categories of Data Processed During a Website Visit

While using the Company's website, the following information about the visitor and the device used for browsing may be collected and processed:

  1. the visitor's IP address;
  2. browser type;
  3. operating system characteristics of the device used for browsing (including language settings);
  4. date and time of the visit;
  5. the visited page(s), functions, or services;
  6. click activity.

These data are retained for a maximum period of 90 days and may primarily be used for investigating security incidents.

3.2. Cookies Used on the Website

3.2.1. Technically Necessary Session Cookies

Purpose of data processing:

To ensure the proper functioning of the website.

These cookies are necessary for visitors to browse the website and fully utilize its functions and services without interruption. Among other things, they enable the website to remember actions performed by the visitor on individual pages and identify logged-in users during a browsing session.

The processing of data by these cookies applies only for the duration of the visitor's current session. Session cookies are automatically deleted from the visitor's device when the browsing session ends or when the browser is closed.

Legal basis for data processing:

Section 13/A (3) of Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (Elkertv.), according to which the service provider may process personal data that are technically indispensable for providing the requested service.

When providing information society services, the service provider must select and operate its technical solutions in such a way that personal data are processed only when strictly necessary for providing the service and fulfilling the purposes defined by law, and only to the extent and for the duration required.

3.2.2. Preference Cookies

These cookies remember the user's preferences, such as how the website should be displayed.

Essentially, these cookies store user-selected settings.

Legal basis for data processing:

The visitor's consent.

Purpose of data processing:

  1. improving the efficiency of the service;
  2. enhancing the user experience;
  3. making the website easier and more convenient to use.

These data are primarily stored on the user's own device, while the website merely accesses them to recognize the returning visitor.

3.2.3. Performance Cookies

These cookies collect information about how users interact with the website, including:

  1. browsing behavior;
  2. time spent on pages;
  3. clicks and user interactions.

These cookies are typically provided by third-party services such as Google Analytics or Google Ads (AdWords).

Legal basis for data processing:

The data subject's consent.

Purpose of data processing:

  1. analyzing website usage;
  2. improving website performance;
  3. providing personalized advertising and marketing offers.

CHAPTER V – INFORMATION ON THE RIGHTS OF THE DATA SUBJECT

I. Summary of the Data Subject's Rights

The data subject has the following rights:

  1. Right to transparent information, communication, and facilitation of the exercise of data subject rights
  2. Right to be informed before personal data are collected directly from the data subject
  3. Right to be informed when personal data have not been obtained directly from the data subject
  4. Right of access
  5. Right to rectification
  6. Right to erasure ("Right to be Forgotten")
  7. Right to restriction of processing
  8. Obligation to notify recipients regarding rectification, erasure, or restriction of processing
  9. Right to data portability
  10. Right to object
  11. Rights relating to automated individual decision-making, including profiling
  12. Restrictions
  13. Right to be informed of a personal data breach
  14. Right to lodge a complaint with a supervisory authority
  15. Right to an effective judicial remedy against a supervisory authority
  16. Right to an effective judicial remedy against the Data Controller or Data Processor

II. Detailed Description of the Data Subject's Rights

1. Transparent Information, Communication and Facilitation of the Exercise of the Data Subject's Rights

1.1. The Data Controller shall provide the data subject with all information relating to the processing of personal data in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, particularly where the information is addressed to children. The information shall be provided in writing or by other means, including, where appropriate, electronically. At the request of the data subject, the information may also be provided orally, provided that the identity of the data subject has been verified by other means.

1.2. The Data Controller shall facilitate the exercise of the data subject's rights.

1.3. The Data Controller shall inform the data subject without undue delay and, in any event, within one month of receiving the request, of the action taken regarding the exercise of the data subject's rights. This period may be extended by a further two months where permitted by the GDPR, provided that the data subject is informed accordingly.

1.4. If the Data Controller does not take action in response to the data subject's request, it shall inform the data subject without undue delay and at the latest within one month of receiving the request of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority or seeking a judicial remedy.

1.5. The Data Controller shall provide information, communications, and actions relating to the data subject's rights free of charge, except where the GDPR permits the charging of a reasonable fee.

Detailed provisions are set out in Article 12 of the GDPR.

2. Right to Prior Information – Where Personal Data Are Collected from the Data Subject

2.1. The data subject has the right to receive information regarding the facts and circumstances relating to the processing of personal data before such processing begins.

The Data Controller shall provide information concerning:

a) the identity and contact details of the Data Controller and, where applicable, its representative;

b) the contact details of the Data Protection Officer, where applicable;

c) the purposes of the intended processing of personal data and the legal basis for the processing;

d) where processing is based on legitimate interests, the legitimate interests pursued by the Data Controller or by a third party;

e) the recipients or categories of recipients of the personal data, where applicable;

f) where applicable, the fact that the Data Controller intends to transfer personal data to a third country or an international organization.

2.2. In order to ensure fair and transparent processing, the Data Controller shall also provide the following additional information:

a) the period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period;

b) the existence of the data subject's right to request access to, rectification or erasure of personal data, restriction of processing, to object to processing, and the right to data portability;

c) where processing is based on consent, the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal;

d) the right to lodge a complaint with a supervisory authority;

e) whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, whether the data subject is obliged to provide the personal data, and the possible consequences of failing to do so;

f) the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

2.3. Where the Data Controller intends to further process personal data for a purpose other than that for which the data were originally collected, the Data Controller shall provide the data subject, prior to such further processing, with information about that other purpose and any relevant additional information.

Detailed provisions concerning the right to prior information are set out in Article 13 of the GDPR.

3. Information to Be Provided Where Personal Data Have Not Been Obtained from the Data Subject

3.1. Where the Data Controller has not obtained the personal data directly from the data subject, the Data Controller shall provide the data subject with the information specified in Section 2 above:

  1. within one month of obtaining the personal data;
  2. if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication with the data subject;
  3. or, if the data are expected to be disclosed to another recipient, no later than the first disclosure of the personal data.

In addition, the Data Controller shall inform the data subject of:

  1. the categories of personal data concerned;
  2. the source of the personal data; and
  3. where applicable, whether the personal data originated from publicly accessible sources.

3.2. The additional provisions set out in Section 2 (Right to Prior Information) shall also apply.

Detailed provisions are contained in Article 14 of the GDPR.

4. Right of Access by the Data Subject

4.1. The data subject has the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them are being processed. Where such processing is taking place, the data subject has the right to access the personal data and the related information referred to in Sections 2 and 3 above.

(Article 15 GDPR)

4.2. Where personal data are transferred to a third country or an international organization, the data subject has the right to be informed of the appropriate safeguards relating to the transfer pursuant to Article 46 of the GDPR.

4.3. The Data Controller shall provide the data subject with a copy of the personal data undergoing processing.

For any additional copies requested by the data subject, the Data Controller may charge a reasonable fee based on administrative costs.

Detailed provisions concerning the right of access are set out in Article 15 of the GDPR.

5. Right to Rectification

5.1. The data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them.

5.2. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

These provisions are set out in Article 16 of the GDPR.

6. Right to Erasure ("Right to Be Forgotten")

6.1. The data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller shall be obliged to erase such personal data without undue delay where one of the following grounds applies:

a) the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;

b) the data subject withdraws the consent on which the processing is based, and there is no other legal ground for the processing;

c) the data subject objects to the processing, and there are no overriding legitimate grounds for the processing;

d) the personal data have been processed unlawfully;

e) the personal data must be erased in order to comply with a legal obligation under Union or Member State law applicable to the Data Controller;

f) the personal data were collected in relation to the offer of information society services directly to a child.

6.2. The right to erasure shall not apply where processing is necessary:

a) for exercising the right of freedom of expression and information;

b) for compliance with a legal obligation under Union or Member State law applicable to the Data Controller, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;

c) for reasons of public interest in the area of public health;

d) for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, where exercising the right to erasure would likely render impossible or seriously impair the achievement of the objectives of that processing; or

e) for the establishment, exercise, or defence of legal claims.

Detailed provisions concerning the right to erasure are contained in Article 17 of the GDPR.

7. Right to Restriction of Processing

7.1. Where processing has been restricted, such personal data shall, with the exception of storage, only be processed:

  1. with the data subject's consent;
  2. for the establishment, exercise, or defence of legal claims;
  3. for the protection of the rights of another natural or legal person; or
  4. for reasons of important public interest of the European Union or of a Member State.

7.2. The data subject has the right to obtain from the Data Controller the restriction of processing where one of the following applies:

a) the data subject contests the accuracy of the personal data, for a period enabling the Data Controller to verify the accuracy of the personal data;

b) the processing is unlawful, and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;

c) the Data Controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise, or defence of legal claims; or

d) the data subject has objected to processing, pending the verification whether the legitimate grounds of the Data Controller override those of the data subject.

7.3. The data subject shall be informed before the restriction of processing is lifted.

The applicable provisions are contained in Article 18 of the GDPR.

8. Notification Obligation Regarding the Rectification or Erasure of Personal Data or the Restriction of Processing

The Data Controller shall communicate any rectification or erasure of personal data or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

At the request of the data subject, the Data Controller shall inform them about those recipients.

These provisions are set out in Article 19 of the GDPR.

9. Right to Data Portability

9.1.

Under the conditions set out in the GDPR, the data subject has the right to receive the personal data concerning them, which they have provided to a Data Controller, in a structured, commonly used, and machine-readable format. The data subject also has the right to transmit those data to another Data Controller without hindrance from the Data Controller to which the personal data were originally provided, where:

a) the processing is based on consent or on a contract; and

b) the processing is carried out by automated means.

9.2.

The data subject may also request the direct transmission of their personal data from one Data Controller to another.

9.3.

The exercise of the right to data portability shall not adversely affect Article 17 of the GDPR, concerning the right to erasure, or the “right to be forgotten.”

The right to data portability shall not apply where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.

The exercise of this right shall not adversely affect the rights and freedoms of others.

The detailed provisions are contained in Article 20 of the GDPR.

10. Right to Object

10.1.

The data subject has the right, on grounds relating to their particular situation, to object at any time to the processing of personal data concerning them where such processing is based on the performance of a task carried out in the public interest or in the exercise of official authority under Article 6(1)(e), or on legitimate interests under Article 6(1)(f), including profiling based on those provisions.

In such cases, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or where the processing is necessary for the establishment, exercise, or defence of legal claims.

10.2.

Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, including profiling to the extent that it is related to such direct marketing.

Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

10.3.

The data subject shall be explicitly informed of these rights no later than at the time of the first communication. This information shall be presented clearly and separately from any other information.

10.4.

The data subject may exercise the right to object by automated means using technical specifications.

10.5.

Where personal data are processed for scientific or historical research purposes or for statistical purposes, the data subject has the right, on grounds relating to their particular situation, to object to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

The applicable provisions are contained in the GDPR.

11. Automated Individual Decision-Making, Including Profiling

11.1.

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

11.2.

This right shall not apply where the decision:

a) is necessary for entering into or performing a contract between the data subject and the Data Controller;

b) is authorized by Union or Member State law applicable to the Data Controller, which also lays down appropriate measures to safeguard the data subject's rights, freedoms, and legitimate interests; or

c) is based on the data subject's explicit consent.

11.3.

In the cases referred to in points a) and c), the Data Controller shall implement appropriate measures to safeguard the data subject's rights, freedoms, and legitimate interests, including at least the right to:

  1. obtain human intervention from the Data Controller;
  2. express their point of view; and
  3. contest the decision.

Further provisions are contained in Article 22 of the GDPR.

12. Restrictions

Union or Member State law applicable to the Data Controller or Data Processor may, by legislative measure, restrict the scope of the rights and obligations provided for in Articles 12–22, Article 34, and Article 5 of the GDPR, provided that such restriction respects the essence of fundamental rights and freedoms.

The conditions applicable to such restrictions are set out in Article 23 of the GDPR.

13. Informing the Data Subject of a Personal Data Breach

13.1.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall inform the data subject of the personal data breach without undue delay.

The communication shall describe the nature of the personal data breach in clear and plain language and shall contain at least the following information:

a) the name and contact details of the Data Protection Officer or another contact point from which further information can be obtained;

b) a description of the likely consequences of the personal data breach;

c) a description of the measures taken or proposed by the Data Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

13.2.

The data subject shall not be required to be informed if any of the following conditions are met:

a) the Data Controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the breach, in particular measures such as encryption that render the personal data unintelligible to persons who are not authorized to access them;

b) the Data Controller has taken subsequent measures ensuring that the high risk to the rights and freedoms of the data subject is no longer likely to materialize;

c) informing the data subject would involve disproportionate effort. In such cases, the data subjects shall instead be informed by means of a public communication or a similar measure through which they are informed in an equally effective manner.

Further provisions are contained in Article 34 of the GDPR.

14. Right to Lodge a Complaint with a Supervisory Authority

The data subject has the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work, or the place of the alleged infringement, if they consider that the processing of personal data relating to them infringes the GDPR.

The supervisory authority with which the complaint has been lodged shall inform the complainant of the progress and outcome of the complaint, including the possibility of a judicial remedy.

These provisions are contained in Article 77 of the GDPR.

Submission of a Complaint

A complaint may be submitted to the Hungarian National Authority for Data Protection and Freedom of Information (hereinafter: NAIH).

Contact details of the NAIH:

Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c., Hungary

Postal Address: 1530 Budapest, P.O. Box 5, Hungary

Telephone: +36 1 391 1400

Website: http://naih.hu/

E-mail: ugyfelszolgalat@naih.hu

15. Right to an Effective Judicial Remedy Against a Supervisory Authority

15.1.

Without prejudice to any other administrative or non-judicial remedy, every natural or legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.

15.2.

Without prejudice to any other administrative or non-judicial remedy, every data subject has the right to an effective judicial remedy where the competent supervisory authority fails to handle a complaint or does not inform the data subject within three months of the progress or outcome of the complaint lodged.

15.3.

Proceedings against a supervisory authority shall be brought before the courts of the Member State where the supervisory authority is established.

15.4.

Where proceedings are brought against a decision of a supervisory authority that was preceded by an opinion or decision of the European Data Protection Board under the consistency mechanism, the supervisory authority shall forward that opinion or decision to the court.

These provisions are contained in Article 78 of the GDPR.

16. Right to an Effective Judicial Remedy Against the Data Controller or Data Processor

16.1.

Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority, every data subject has the right to an effective judicial remedy where they consider that their rights under the GDPR have been infringed as a result of the processing of their personal data in violation of the GDPR.

16.2.

Proceedings against a Data Controller or Data Processor shall be brought before the courts of the Member State where the Data Controller or Data Processor has an establishment.

Such proceedings may also be brought before the courts of the Member State where the data subject has their habitual residence, unless the Data Controller or Data Processor is a public authority of a Member State acting in the exercise of its public powers.

These provisions are contained in Article 79 of the GDPR.

Issued in Budapest on 27 March 2026.

Contact Details

  • GOLDEN HOOK Kft.
  • 2823, Vértessomló,
    Üdülőfalu
  • Registration number: 11-09-031352
  • Tax number: 32708996-2-11